×

Group authentication method

  • US 8,005,460 B2
  • Filed: 02/05/2008
  • Issued: 08/23/2011
  • Est. Priority Date: 08/24/2007
  • Status: Active Grant
First Claim
Patent Images

1. A group authentication method adaptable to a communication system, wherein the communication system comprises a first group, a serving network, and a home network, the first group comprises at least one mobile station, the serving network has a first database for recording a plurality of group lists and group authentication data received from the home network, the home network pre-distributes a group authentication key and a mobile station authentication key to the mobile station and itself, the home network has a second database for recording the group lists generated by the home network, and the group authentication method comprises:

  • identifying action to the mobile station through the serving network; and

    determining whether the communication system performs a full authentication action or a local authentication action through the serving network according to the result of the identification action, anda mobile station authentication and key distribution step;

    wherein the full authentication action comprises;

    the execution of the home network authentication, the mobile station authentication, and key distribution;

    wherein the local authentication action comprises;

    a transient authentication key obtaining step, wherein the transient authentication key obtaining step comprises;

    retrieving the group authentication data from the first database through the serving network, wherein the group authentication data contains which contains a group transient key (GTK) generated at the home network according to the group authentication key;

    wherein the group list comprises a group number, the group authentication key, a mobile station ID, an initial value, and a group related message, and the mobile station has the group number, the mobile station ID, and the initial value;

    wherein the identification action comprises;

    requesting an identification data from the mobile station through the serving network;

    generating a first random number through the mobile station, and then generating the identification data according to the mobile station authentication key and the first random number through the mobile station; and

    transmitting the identification data to the serving network from the mobile station;

    wherein the mobile station has a mobile station authentication message generation function, and the method for generating the identification data comprises;

    inputting the first random number and the mobile station authentication key into the mobile station authentication message generation function stored in the mobile station to calculate a first message authentication code (MAC); and

    combining the group number, the mobile station ID, the first random number, and the first MAC through the mobile station to generate the identification data.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×